FUJIFILM Multifunction Printers Out-of-Bounds Write Vulnerability Leading to Denial-of-Service

Vulnerability

An out-of-bounds write vulnerability has been identified in several FUJIFILM multifunction printers, including the DocuPrint CP225w and CP228w models, as well as the CM225fw and CM228fw models, all running specific firmware versions or earlier. This vulnerability arises from inadequate verification of data length, allowing for out-of-bounds writes that can lead to a denial-of-service condition. When an affected printer processes a specially crafted printer job file, it may freeze, requiring a reboot to recover.

Impact

Exploitation of this vulnerability can cause the printer to freeze while processing an invalid print job file, creating a denial-of-service condition that requires a manual reboot to resolve.

Remediation

Users are advised to update the printer's firmware to the latest version. For the CP225w and CP228w models, the fixed version is 01.23.02 or later. For the CM225fw and CM228fw models, the fixed version is 01.12.02 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.